Skip to main content
Reference — generated from the toolkit

Source of truth: toolkit/registers/README.md. Edit it there; this page is regenerated on build.

Registers

Living registers — each a canonical list with a fixed schema, every entry linked to its evidence. A finding that isn't in the right register doesn't exist.

Schemas are defined; rows are populated as their source activities run (mostly STOP). Defined: tech-debt-register.md, security-debt-register.md, eol-inventory.md, security-exceptions.md. Still to define:

RegisterPopulated byOwner
Client-commitment registerSTOP client triageDelivery
Tech-debt registertech-debt auditEngineering
Security-debt registersecurity-gap assessmentSecurity
Risk-acceptance recordsany gate / STOP exitEngineering + Security
Security exception / waiver registergate waiversSecurity
Client & market signal registerCommercial + SupportProduct
Gate-waiver logall gatesgate owners

Waivers and accepted risks always carry a named owner and a hard expiry after which the gate re-blocks.